Nationwide delivery across South Africa
Johannesburg & GautengCape Town & Western CapeDurban & KwaZulu-NatalPretoria & TshwanePort Elizabeth & Eastern CapeBloemfontein & Free StatePolokwane & LimpopoNelspruit & MpumalangaKimberley & Northern CapeNamibia ยท Botswana ยท ZimbabweJohannesburg & GautengCape Town & Western CapeDurban & KwaZulu-NatalPretoria & TshwanePort Elizabeth & Eastern CapeBloemfontein & Free StatePolokwane & LimpopoNelspruit & MpumalangaKimberley & Northern CapeNamibia ยท Botswana ยท Zimbabwe

๐Ÿ”’ Privacy & Data Protection

Privacy Policy

POPIA 4/2013 compliant (incl. April 2025 amendments) Google Merchant Center approved ECT Act 25/2002 Effective: 1 April 2026
๐Ÿ›ก POPIA 4/2013 ๐Ÿ›ก ECT Act 25/2002 ๐Ÿ›ก CPA 68/2008 ๐Ÿ›ก Google Merchant Center ๐Ÿ›ก GDPR-aligned

This policy meets South African data privacy law including the April 2025 POPIA amendments and Google Merchant Center requirements for Shopping listings.

1 Who We Are & How to Contact Us

This Privacy Policy is published by Coffee & Blenders SA (“we”, “us”, “our”), operator of coffeeandblenders.co.za โ€” a South African online retailer of Italian espresso machines, coffee grinders and Thermomixยฎ appliances.

Under the Protection of Personal Information Act 4 of 2013 (POPIA), Coffee & Blenders SA is the Responsible Party that determines the purpose of and means for processing your personal information.

Information Officer & Contact Details

Business NameCoffee & Blenders SA
Physical Address92 Main Rd, Walmer, Gqeberha (Port Elizabeth), Eastern Cape, 6070, South Africa
Email (General & Privacy)sales@coffeeandblenders.co.za
JurisdictionRepublic of South Africa โ€” Eastern Cape
โ„น๏ธ
For any privacy enquiry, to exercise your data subject rights, or to complain about how we handle your personal information, email sales@coffeeandblenders.co.za with “POPIA Request” in the subject line. We respond within 3 business days.

2 What Personal Information We Collect

Under Section 18 of POPIA we must inform you of the personal information we collect. We only collect information that is adequate, relevant and not excessive for the stated purposes.

Information you give us directly

CategoryInformationWhen Collected
IdentityFull name, titleAccount, checkout, contact form
ContactEmail address, phone number, physical address, provinceAccount creation, checkout, enquiries
DeliveryDelivery address, recipient name, instructionsOrder placement
TransactionOrder history, products purchased, amounts, invoice detailsEach purchase
Payment methodPayment type only โ€” full card numbers processed by SSL-secured payment gateway, not by usCheckout
CommunicationEnquiry content, support requests, returns correspondenceContact form, email
Marketing preferencesConsent status, opt-out historyAccount setup, checkout, email sign-up

Information collected automatically

CategoryInformationMethod
TechnicalIP address, browser type, device type, operating systemServer logs, cookies
UsagePages visited, products viewed, time on site, click behaviourCookies, Google Analytics
LocationGeneral geographic location derived from IP (province-level only)Google Analytics
SessionCart contents, session ID, referring websiteWooCommerce session cookies
โš ๏ธ
We do not collect: Sensitive special categories of personal information such as race, health data, biometric data, religious or political beliefs, or sexual orientation. We do not knowingly collect personal information from children under 18 without verified parental consent, in line with Section 35 of POPIA.

3 How We Use Your Personal Information

We process your personal information only for specific, explicitly defined and lawful purposes. The legal bases available under Section 11 of POPIA are: consent (s.11(1)(a)), performance of a contract (s.11(1)(b)), legal obligation (s.11(1)(c)), protection of legitimate interests (s.11(1)(f)), and the operator relationship (s.11(1)(g)).

PurposeLegal Basis (POPIA s.11)Data Used
Processing and fulfilling your orderContract (s.11(1)(b))Identity, contact, delivery, payment, transaction
Order confirmations & delivery updatesContract (s.11(1)(b))Email, order details
Returns, refunds & warranty processingContract / Legal obligation (s.11(1)(b)(c))Identity, contact, transaction, payment
Customer service & supportLegitimate interest / Contract (s.11(1)(b)(f))Identity, contact, communication
Marketing emails (with consent or existing customer)Consent (s.11(1)(a)) / Section 69 existing customerEmail, preferences, purchase history
Website analytics & improvementLegitimate interest (s.11(1)(f))Technical, usage data (anonymised)
Fraud prevention & securityLegitimate interest / Legal obligation (s.11(1)(c)(f))Identity, technical, transaction
Legal compliance & record-keepingLegal obligation (s.11(1)(c))Identity, contact, transaction
โœ…
We will never: Sell your personal information to third parties. Use your personal information in advertisements without explicit consent. Send unsolicited marketing without a valid POPIA legal basis. Collect your information primarily for the purpose of sharing it with others. These commitments align with Google Merchant Center’s requirement to collect user information responsibly and securely.

4 Who We Share Your Information With

We share personal information with third parties only where strictly necessary to operate our business and fulfil our obligations to you. We do not sell, rent or trade personal information. All third parties are contractually required to handle your information in accordance with POPIA.

Third PartyPurposeInformation Shared
Courier partners (e.g. Aramex, Courier Guy)Delivering your order nationwideName, delivery address, phone, order reference
SSL-secured payment gatewayProcessing your payment securelyPayment data processed directly by gateway โ€” we do not receive or store full card numbers
WooCommerce / WordPress hostingWebsite and e-commerce platformAccount data, orders, technical data
Google LLC (Analytics, Ads, Merchant Center)Analytics, Shopping listings, advertisingAnonymised usage data, cookie IDs โ€” no name or email shared with Google for analytics purposes
Email service providerTransactional and marketing emailsEmail address, name, order details
Manufacturer warranty partners (Vorwerk, Gaggia, Lelit, Wega, Eureka, Macap, Presso, Rocket, Nurri)Warranty and after-sales claims you initiateName, contact, product serial number, proof of purchase
Accounting softwareFinancial records and tax complianceInvoice and transaction data
SARSStatutory tax obligationsBusiness transaction records as legally required
Law enforcement / courtsLegal obligation, fraud prevention, dispute resolutionOnly as required by valid legal process or court order

International data transfers

Some service providers are based outside South Africa โ€” including Google LLC (United States). When we transfer personal information internationally, we ensure adequate safeguards are in place as required by Section 72 of POPIA, including standard contractual obligations requiring recipients to uphold POPIA principles and maintain protection standards substantially similar to South African law.

5 Cookies & Tracking Technologies

Our website uses cookies โ€” small text files stored on your device โ€” to provide a functional shopping experience, analyse site usage, and (with your consent) personalise content and advertising. In line with POPIA and Google Merchant Center requirements, we obtain your consent before placing non-essential cookies.

Cookies we use

Cookie / ServicePurposeDuration
Essential โ€” Always Active (no consent required)
woocommerce_cart_hashMaintains your shopping cart between pagesSession
woocommerce_sessionTracks session and checkout progress2 days
wp-settings-*Stores WordPress preferences for logged-in users1 year
PHPSESSIDPHP session identifier โ€” server-side session stateSession
Analytics โ€” Requires Consent
_ga / _gid (Google Analytics)Tracks anonymised website usage to help us improve the site2 years / 24h
_gat (Google Analytics)Throttles Google Analytics request rate1 minute
Marketing / Advertising โ€” Requires Consent
_gcl_au (Google Ads)Measures Google Shopping ad effectiveness and conversions3 months
IDE / DSID (Google)Used by Google to show relevant ads based on browsing13 months
NID (Google)Stores preferences and enables Google Shopping features6 months
Preference โ€” Requires Consent
currency / languageRemembers your preferred currency and language30 days

Managing your cookie consent

  • Use the cookie consent banner on your first visit to set or update your preferences
  • Clear cookies from your browser settings at any time to reset consent
  • Opt out of Google Analytics: tools.google.com/dlpage/gaoptout
  • Manage Google ad personalisation: adssettings.google.com
  • Withdrawing non-essential cookie consent will not affect your ability to shop on our site
โ„น๏ธ
Google Shopping: Google may use cookies when your product listings appear on Google Shopping to measure how many people view them. This is governed by Google’s Privacy Policy. You can control ad personalisation at adssettings.google.com.

6 Your Rights as a Data Subject

Under POPIA Chapter 2, Section 5, you have the following rights regarding your personal information. Exercise any right by emailing sales@coffeeandblenders.co.za with “POPIA Request โ€” [Right Type]” in the subject line. We will respond within 30 days of receiving a complete, valid request and may require proof of identity.

๐Ÿ“‹
Right to be Notified
You have the right to be informed when your personal information is collected and about the purposes for which it is used. This Privacy Policy fulfils that obligation.
๐Ÿ”
Right of Access (Section 23)
You have the right to request a copy of the personal information we hold about you. We will provide this within 30 days. A reasonable fee may apply per the Promotion of Access to Information Act.
โœ๏ธ
Right to Correction (Section 24)
You may request that we correct, update or complete inaccurate or incomplete personal information we hold about you.
๐Ÿ—‘๏ธ
Right to Deletion (Section 24)
You may request deletion of your personal information where we no longer have a lawful basis to retain it, subject to our legal retention obligations.
๐Ÿšซ
Right to Object (Section 11)
You have the right to object to processing based on legitimate interest grounds. We will cease processing unless we can demonstrate compelling legitimate grounds that override your rights.
๐Ÿ“ต
Opt Out of Marketing (Section 69)
You may opt out of direct marketing communications at any time by clicking “unsubscribe” in any email, or by contacting us. We will process opt-outs within 10 business days.
๐Ÿ“‚
Right to Data Portability
You may request your personal information in a commonly used, machine-readable format where technically feasible, to allow transfer to another service provider.
โš–๏ธ
Right to Lodge a Complaint
If you believe we have violated your POPIA rights, you may complain to the South African Information Regulator โ€” contact details in Section 11 below.

7 How Long We Keep Your Information

We retain personal information only as long as necessary to fulfil the purposes for which it was collected, or as required by South African law. Personal information that is no longer needed is securely deleted, anonymised or de-identified.

Data CategoryRetention PeriodReason
Order and transaction records5 years from transaction dateSARS tax and VAT obligations, CPA warranty records
Customer account informationDuration of account + 3 years after closureLegitimate business interest, legal compliance
Warranty and returns records2 years from date of purchaseManufacturer warranty coverage period
Marketing consent recordsUntil consent withdrawal + 3 yearsPOPIA Section 69 โ€” proof of lawful basis
Support and correspondence3 years from last correspondenceDispute resolution and legal defence
Google Analytics data26 months (Google’s standard)Website improvement and performance analysis
Security and fraud logs12 monthsFraud detection and incident response

8 How We Protect Your Information

We implement appropriate technical and organisational security measures as required by Section 19 of POPIA and Google Merchant Center guidelines to protect your personal information against unauthorised access, accidental loss, destruction, alteration or disclosure.

  • SSL/TLS encryption: All data between your browser and coffeeandblenders.co.za is encrypted via HTTPS โ€” as required by Google Merchant Center for collecting personal and payment information
  • Payment security: We do not store full credit or debit card numbers. Payment data is processed exclusively by our SSL-secured, PCI-DSS compliant payment gateway
  • Access controls: Access to personal information is restricted to authorised personnel who need it to perform their job functions
  • Platform security: Our WooCommerce and WordPress platform is maintained with current security patches and updates
  • Data minimisation: We collect only information necessary for the stated purpose, in line with POPIA’s minimality principle (Section 10)

Data breach notification

In the event of a security compromise involving your personal information that is likely to result in serious harm, we will notify you and the South African Information Regulator as soon as reasonably possible โ€” as required by Section 22 of POPIA and the April 2025 amended POPIA Regulations. Our notification will describe the nature of the breach, the information involved, and the remedial steps taken.

โš ๏ธ
Despite our security measures, no internet transmission can be guaranteed 100% secure. If you believe your interaction with us has been compromised, please notify us immediately at sales@coffeeandblenders.co.za.

9 Direct Marketing & Email Communications

We may send you marketing communications in the following circumstances, in line with Section 69 of POPIA and the Information Regulator’s 2024/2025 Guidance Note on Direct Marketing:

When we may contact you

  • Existing customers: We may email you about similar products to those you have previously purchased using your checkout email address โ€” unless you have opted out
  • With your consent: If you have expressly opted in during account creation, checkout or via an email sign-up form
  • Transactional emails: Order confirmations, dispatch notifications and returns updates are always sent regardless of your marketing preference โ€” these form part of your purchase contract

How to opt out at any time

  • Click the “Unsubscribe” link in the footer of any marketing email โ€” removed within 10 business days
  • Email sales@coffeeandblenders.co.za with “Unsubscribe” in the subject line
  • Opting out of marketing does not affect transactional emails about your orders
๐Ÿ“‹
POPIA Section 69: Consent is the default requirement for all unsolicited electronic marketing (emails, SMS, automated calls). We will not send you unsolicited marketing unless we have a valid POPIA legal basis. Your right to opt out is always available and will be honoured promptly.

10 Third-Party Links & Google Shopping

Our website may contain links to third-party websites including manufacturer sites, review platforms and social media. We are not responsible for the privacy practices of these external sites โ€” please review their privacy policies before providing personal information.

Google Shopping & Google Merchant Center

Our products are listed on Google Shopping via Google Merchant Center. When you click a Google Shopping listing and visit our site, Google may have already collected information about your search behaviour. That collection is governed by Google’s Privacy Policy. On our website, we collect your information as described in Sections 2 and 5 of this policy.

โœ…
In accordance with Google Merchant Center requirements: we do not use personal information collected from our website in third-party advertisements without your consent. Our website’s primary purpose is to sell premium coffee equipment โ€” not to collect personal information for resale or sharing with advertising networks.

11 Complaints & the South African Information Regulator

If you are concerned about how we handle your personal information, please contact us first at sales@coffeeandblenders.co.za. We will investigate and respond within 30 days.

If you are not satisfied with our response, or believe we have violated your POPIA rights, you have the right to lodge a formal complaint with the South African Information Regulator:

Information Regulator โ€” South Africa

Postal AddressJD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Penalty (POPIA violations)Up to ZAR 10 million fine or 10 years imprisonment, or both

12 Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in South African law (including POPIA amendments), Google Merchant Center requirements, or our data processing practices. The revised policy will be published on this page with an updated effective date.

Where a material change affects how we use your personal information, we will notify you by email or by prominent notice on our website at least 14 days before the change takes effect. Continued use of coffeeandblenders.co.za after the effective date constitutes acceptance of the revised policy.

Effective date: 1 April 2026  |  Version: 2.0  |  Jurisdiction: Republic of South Africa

Questions About Your Privacy?

Email sales@coffeeandblenders.co.za with “POPIA Request” in the subject line โ€” we respond within 3 business days.

Legal notice: This Privacy Policy is designed to comply with the Protection of Personal Information Act 4 of 2013 (POPIA) including April 2025 amended Regulations, the Electronic Communications and Transactions Act 25 of 2002, the Consumer Protection Act 68 of 2008, and Google Merchant Center requirements as of April 2026. This policy is a general guide and does not constitute legal advice. In the event of any conflict between this policy and applicable South African legislation, the legislation prevails.